首页> 外文会议>IEEE International Conference on Computer Research and Development >From Real Malicious Domains to Possible False Positives in DGA Domain Detection
【24h】

From Real Malicious Domains to Possible False Positives in DGA Domain Detection

机译:从真正的恶意域到DGA域检测中可能的误报

获取原文

摘要

Various families of malware use domain generation algorithms (DGAs) to generate a large number of pseudo-random domain names to connect to malicious command and control servers (C&Cs). These domain names are used to evade domain based security detection and mitigation controls such as firewall controls. Existing prevalent techniques to detect DGA domains such as reverse engineering malware samples and statistical analysis techniques are time consuming, can be easily circumvented by attackers, and need contextual information which is not easily or feasibly obtained. Due to this, the use of machine learning and deep learning techniques to detect DGA domains has picked up significant interest in the cyber security and analytics communities. The ultimate goal is to detect DGA domains on a per domain basis using the domain name only, with no additional information. As with all techniques, there is the possibility of false positives: valid domains being detected as DGA domains. This paper explores the possible use cases that can result in false positives for DGA domain detection using machine learning and deep learning techniques, and how such use cases, if not uniquely addressed within an automated system or model or technique, can also be used as attack vectors by attackers using DGA domains.
机译:的恶意软件使用域生成算法(DGAs)各种家庭产生大量伪随机域名连接到恶意命令和控制服务器(C&Cs)的。这些域名是用来逃避域基于安全检测和缓解控制,例如防火墙对照。现有流行的技术来检测逆向工程的恶意软件样本和统计分析技术是耗时的,可以被攻击者轻易规避,并且需要其中不容易或可行地获得上下文信息DGA域这样。由于这个原因,利用机器学习和深入学习技术来检测DGA域回升在网络安全和分析社区显著的兴趣。最终的目标是只检测使用域名每一个域基础上DGA域,没有其他信息。如同所有的技术,存在误报的可能性:被检测有效域作为DGA域。本文探讨了可能的使用情况下,可以使用机器学习和深入学习技术导致误报DGA域检测,以及如何这样的使用情况下,如果不是唯一的自动化系统或模型或技术之内解决,也可以用来作为攻击通过使用DGA域攻击向量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号